Security and privacy

NounDesk manages devices, not people.

NounDesk collects only what device management needs: device identity, hardware and OS details, installed managed apps, compliance state, and location only during lost mode. It never collects calls, messages, browsing history, keystrokes or personal content. Every organization's data is isolated at the database level, administrator roles follow least privilege, every action is audited, destructive actions require typed confirmation, and hosting is on Vercel and Supabase in the US region with encryption in transit and at rest.

What we collect

  • Device identity: name, serial number, IMEI where the device reports it
  • Hardware and OS details: model, manufacturer, Android version, security patch date, storage, network operator
  • Installed managed apps and their versions
  • Compliance state against your policy
  • Location, including a trail of recent locations, only while a device is in lost mode
  • Company documents you choose to share, and a record of who opened each one and when
  • Administrator actions, for the audit log

What we never collect

  • Call logs, SMS or messages of any kind
  • Browsing history
  • Keystrokes or screen contents
  • Personal files, photos or app content
  • Location outside lost mode
  • Battery level outside lost mode (Android does not report it)

Tell your team this on day one. We would rather be the tool that is easy to explain.

How your data is protected

  • Isolation. Every organization's data is isolated at the database level with row-level security. No customer can see another's devices.
  • Least privilege. Four administrator roles, Owner, Admin, Operator and Viewer, so day-to-day staff cannot erase devices or change policies. See team and roles.
  • Everything is audited. Every administrator action is recorded with actor, target, result and time, and the log cannot be edited. See reports and audit.
  • Google credentials stay on the server. They never appear in the browser after connection. Enrollment codes are never stored or logged.
  • Destructive actions are deliberate. Erase requires typing the device name. There is no bulk erase. Nothing is wiped automatically when an employee leaves.
  • Hosting. Vercel and Supabase, US region, encrypted in transit and at rest by the platforms.

How the device is protected

Your security policy decides: screen lock strength, storage encryption, Google Play Protect, apps from Google Play only, USB data transfer, update schedule. Security patches are never delayed by NounDesk. Policies can also block printing, SD cards and USB drives, screenshots and USB file transfer (data protection). If a phone is lost, lost mode locks it and erase keeps factory reset protection on, so the phone will not set up again until one of your company's Google accounts signs in.

What NounDesk is built on

NounDesk uses Android Enterprise, Google's own management framework built into every certified Android device. There is no custom agent app on the phone, so there is nothing of ours to keep patched on the device, and the permissions NounDesk has are exactly the ones Google grants a device owner: no more.

Roadmap items we list honestly

Two-factor authentication for administrators and personal-device work profiles are planned and not yet shipped. We list them as roadmap, not features. Zero-touch enrollment has shipped for phones bought through an authorized zero-touch reseller.

Unfamiliar terms

Factory-reset protection, Play Protect, patch level and the rest are explained in plain English in the glossary.

Questions or reports

Write to support@noundesk.com. If you believe you have found a security issue, please say so in the subject line and we will prioritise it.

Privacy and security questions

Can NounDesk read my employees' messages or see their browsing?

No. NounDesk does not collect call logs, SMS or messages, browsing history or keystrokes, and cannot read the content of any app. It manages the device, not the person.

Does NounDesk track location?

Only while a device is in lost mode, and only because you turned it on. Outside lost mode no location is collected at all.

Where is my data hosted?

On Vercel and Supabase in the United States, encrypted in transit and at rest by those platforms.

Can another NounDesk customer see my devices?

No. Every organization's data is isolated at the database level with row-level security.

Are Google credentials stored?

Google credentials never leave the server, and enrollment codes are never stored or logged.

Does website filtering record which sites employees visit?

No. Website filtering sends your block list or allow-list to Google Chrome on the phone. NounDesk does not receive or store browsing history.

Can NounDesk see a phone's screen during remote support?

No. Remote support sessions run in your own TeamViewer, AnyDesk or Splashtop account and app. NounDesk installs and links the vendor app and opens its console; the session itself happens in the vendor's app.

Is there two-factor authentication for administrators?

Not yet; it is on the roadmap. Use strong, unique passwords for administrator accounts in the meantime.

Protect the phones without watching the people.

Start a free trial, or load a sample fleet in demo mode first.